Website Watch

Always-on website monitoring

Daily pulse for headers, certificate expiry, and exposed paths. Pick Standard or Deep for the weekly scan when you add the site. Email when something new appears. From $29 per site per month.

Coverage

What is included

Daily pulse on every seat. Weekly Standard or Deep, locked at checkout. Credits are not charged for included runs.

Daily pulse

Each day Watch checks TLS and certificate days remaining, security headers, mixed content, HTTP to HTTPS, and common exposed paths. This is a lightweight origin check, not a ZAP-backed Standard scan.

Weekly Standard or Deep

When you add a site, pick Standard (~5-7 minutes, ~80 checks) or Deep (~12-15 minutes, ~120 checks) for the weekly scan. That depth is locked for the seat. Open the run from scan history when you need the full finding list. Comprehensive stays on credits.

Delta alerts

After the first baseline, you get email when something new or worse appears, when the score drops past your threshold, or when the certificate hits 30, 14, 7, or expired. Mute noisy findings. Unmute them from the same watch page.

One seat per site

Standard is $29 per site per month ($290/year). Deep is $49 ($490/year). Pause keeps the paid seat. Cancel drops it at period end. Unused seats only attach to a new origin of the same depth. Included pulse and weekly runs do not use credits.

See pricing · Scheduled Scans stay on credits for custom cadence.

After a scan

Keep the origin in view

A dashboard scan is a snapshot. Watch is the daily pulse and weekly Standard or Deep that follows.

After you finish a scan, add the same HTTPS origin to Watch when you want change alerts instead of another one-off credit run. Daily pulse plus weekly Standard or Deep. Included runs do not use credits. Standard is $29 per site per month. Deep is $49.

Still deciding between a scan, Watch, and a pentest? Website Security Scanner · $297 Penetration Test · $497 Comprehensive Pentest.

How to

How to set up Watch

Add one HTTPS origin per seat. Pick Standard or Deep. Checkout opens when you need another seat of that depth.

  1. Open Watch

    Sign in and go to /watch. The Watch item sits next to Scheduled. The dashboard card shows how many sites you are watching versus paid seats.

  2. Add an HTTPS origin

    Enter a name such as Shop production, the HTTPS URL, monthly or yearly billing, and Standard or Deep. Click Watch website. Unused paid seats attach only when they match that depth. Otherwise Stripe Checkout opens for a new seat.

  3. Let the baseline finish

    The first pulse and first weekly Standard or Deep scan record what already exists. You should not expect an inbox full of historical findings on day one. Open the watch to see last pulse, last weekly scan, and certificate days.

  4. Tune alerts, then mute noise

    Set new findings, resolved findings, score drop, minimum severity, quiet hours, timezone, extra recipients, and weekly digest. Mute accepted risk. Click Unmute on that row or under Muted issues when you want alerts again.

Expectations

What to expect

Watch answers whether the public origin changed. It is not a pentest and not a custom-depth scheduler.

Standard or Deep at add-site, then locked

Pick Standard or Deep when you add the site. Daily pulse is the same on every seat. Quick and Comprehensive are not Watch tiers; run those from the dashboard with credits, or use Scheduled Scans for a custom calendar.

Quiet first day is correct

Baseline runs do not spam existing findings. Alerts start when the site changes, the score drops, or a cert window is hit.

Manual runs are rate-limited

Run pulse now is limited to once per 15 minutes. Run weekly Standard now or Run weekly Deep now is limited to once per 6 hours. The included daily and weekly schedule still runs on its own.

Examples

Worked examples

How Watch looks for agencies, certificate expiry, and accepted staging risk.

Agency watching five shops

Add five HTTPS origins on monthly Standard. Stripe quantity becomes five. Occupied seats show Watching 5 of 5. Included runs do not consume credits. A Deep origin is a separate $49 seat, not an extra Standard quantity.

Five Standard seats: $145 per month. Mix in Deep at $49 each.

Certificate 12 days from expiry

A pulse records the tightest window, 14 days, then later 7 days, then expired. Quiet hours can delay the mail until morning in the watch timezone.

One alert per window, not a daily cert nag.

Mute staging HSTS, then unmute

Staging is missing HSTS on purpose. Mute it. The row shows a Muted pill and Unmute. Production still alerts. When staging should be strict, click Unmute.

Alerts resume for that fingerprint only.
Compare

Watch versus Scheduled Scans versus pentest

Pick the product that matches the question you need answered.

ProductCadenceBillingCreditsBest for
Website WatchDaily pulse + weekly Standard or DeepStandard $29 / Deep $49 per site / monthIncluded runs use noneKnow when the public origin changed
Scheduled ScansCustom calendar and depthPlan or creditsYesRepeat Comprehensive or a custom weekday
Penetration TestOne engagement plus retests$297 or $497Separate productVerified automated evidence-backed testing
Alerts

How to mute and unmute

Silence one accepted finding without turning Watch off.

  1. Open the watch

    Go to /watch, click the site, and find the finding under Open issues.

  2. Mute accepted risk

    Click Mute. The row shows a Muted pill and is listed under Muted issues. Later pulses still see the issue, but that fingerprint drops out of new-finding email.

  3. Unmute when you want alerts again

    Click Unmute on the same open-issue row, or in Muted issues. Alerts for that fingerprint resume on later change detection. You do not need support to clear a mute. Do not turn off New findings globally to hide one staging quirk.

Step-by-step setup, troubleshooting, and more examples live in Website Watch documentation and Website Watch help.

FAQ

Website Watch FAQ

Billing, credits, mute, and how Watch differs from Scheduled Scans and pentest.

Watch is always-on monitoring for one HTTPS origin. Vulnify runs a daily pulse (headers, certificate expiry, exposed paths) and one weekly Standard or Deep scan, chosen when you add the site. You get an email when something new appears.

Start watching an origin

Add an HTTPS site, pay per seat, and get mail when the public surface changes.